Skip to content

Malware

Sturnus

According to ThreatFabric, Sturnus is a privately operated Android banking trojan.

Sturnus is a Android malware family.

Background

ThreatFabric describes Sturnus as a privately run Android banking trojan offering a wide spread of fraud features, up to and including full device takeover. What sets it apart is its capacity to defeat encrypted messaging: by reading content straight off the device screen after it has been decrypted, Sturnus can follow conversations in WhatsApp, Telegram, and Signal.

The trojan steals banking credentials using believable fake login overlays that mimic legitimate banking apps. It also hands attackers broad remote control, letting them watch everything the user does, inject text without any physical interaction, and even blank the screen while carrying out fraudulent transactions in the background, all without the victim noticing.


Source: Malpedia (Fraunhofer FKIE).